Categories: Uncategorized

Facebook Privacy Loophole Cloaks Deactivated Friends, Allows Unexpected Creeping

A research student at University College London, Shah Mahmood, and UCL’s Chair of Information Communication, Yvo Desmedt, have announced details of “a zero-day privacy fault” in Facebook at the IEEE International Workshop on Security and Social Networking conference in Switzerland on Monday. They explain that the “Deactivated Friend Attack” works like this:

Our deactivated friend attack occurs when an attacker adds their victim on Facebook and then deactivates her own account. As deactivation is temporary in Facebook, the attacker can reactivate her account as she pleases and repeat the process of activating and deactivating for unlimited number of times. While a friend is deactivated on Facebook, she becomes invisible. She could not be unfriended (removed from friend’s list) or added to any specific list.

Mahmood and Desmedt say in the abstract of the paper they presented that “it is highly probable the attacker has indefinite access to the victims private information in a cloaked way.” The pair note a complicating factor, which is that Facebook users are not notified when their friends deactivate or reactivate their own accounts, which could lead to surprise snooping. They revealed this vulnerability and its potential impact “by showing the ease of gaining trust of Facebook users and being befriended online.”  From a bogus account set up for the purposes of the 600 day experiment, Mahmood and Desmedt used targeted friend requests during the first 285 days, during which they sent out 595 friend requests. Of those, 370 were accepted. The dummy account received 3,969 friend requests, which the pair accepted. Ultimately, the phony account accrued about 4,300 friends and maintained access to their Facebook profile information for at least 261 days, according to their paper. “No user was able to unfriend us during this time due to cloaking and short de-cloaking sessions. The short de-cloaking sessions were enough to get updates about the victims.” Finally, they reactivated the account and left it idle for 60 days to see how many people unfriended them – 239 people unfriended, just over five percent of the total. The most pernicious aspect of the Deactivated Friend Attack is that it’s hard to track and hard to prevent. Despite this, Mahmood and Desmedt suggest that fixing the problem should be fairly straightforward. They suggest a number of strategies Facebook could take to ameliorate the issue, including notifying users when their friends deactivate their accounts and flagging users who frequently deactivate and reactivate their accounts. It’s uncertain whether Facebook will take action on this problem and whether Mahmood and Desmedt’s proposed fixes make sense for the social networking giant. For now, this vulnerability is tacked onto the long list of privacy issues with which Facebook must contend. Facebook has not yet released a statement about Mahmood and Desmedt’s findings.

Techli

Edward is the founder and CEO of Techli.com. He is a writer, U.S. Army veteran, serial entrepreneur and chronic early adopter. Having worked for startups in Silicon Valley and Chicago, he founded, grew and successfully exited his own previous startup and loves telling the stories of innovators. Email: Edward.Domain@techli.com | @EdwardDomain

Share
Published by
Techli

Recent Posts

HostMilano 2025: AI and Automation Transform Professional Kitchen Operations

HostMilano 2025 concluded its 44th edition on October 26 and remains the premier world fair…

3 días ago

Prezent AI reaches latest milestone following recognition as top software company in 2025

As the new year approaches, the Software Report—a trusted source for market research and industry…

3 días ago

Ness Digital Engineering and Vendavo to usher in new era of AI-led innovation

Now that AI has been on the scene for a number of years, we can…

3 días ago

AI is reengineering orthopedic systems through new multi-layer software architectures

The rapid evolution of orthopedic technology is no longer being driven by devices alone. Instead,…

2 semanas ago

Digital credentialing enters a new phase with the arrival of I.C.E. Exchange 2025 in Phoenix

The credentialing industry’s calendar is turning toward Phoenix this month, where the I.C.E. Exchange will…

2 semanas ago

Tax season gets an upgrade as Deduction raises $2.8M and launches its AI-powered tax agent

Deduction today announced the launch of “Taylor, CPAI,” the first AI tax accountant built for…

2 semanas ago